Skip to main content

Vendor/product archive

apache / apache-airflow-providers-ftp CVEs

Beta · best-effort

2 CVEs tagged to apache / apache-airflow-providers-ftp0 Critical, 1 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-49486

Published Jun 26, 2026

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the d…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-29733

Published Apr 21, 2024

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1